From 0fcf45b1317a6e27f613542c6d6cb1511efc134c Mon Sep 17 00:00:00 2001 From: 0xd34df00d <0xd34df00d@gmail.com> Date: Wed, 2 Oct 2019 21:51:39 -0400 Subject: [PATCH] Set SNI in the openssl backend --- src/vmime/net/tls/openssl/TLSSocket_OpenSSL.cpp | 6 ++++++ src/vmime/net/tls/openssl/TLSSocket_OpenSSL.hpp | 2 ++ 2 files changed, 8 insertions(+) diff --git a/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.cpp b/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.cpp index db782bb2..8ab75439 100644 --- a/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.cpp +++ b/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.cpp @@ -123,6 +123,10 @@ void TLSSocket_OpenSSL::createSSLHandle() { if (m_wrapped->isConnected()) { + if (m_address.empty()) { + throw exceptions::tls_exception("Unknown host name, will not be able to set SNI"); + } + #if OPENSSL_VERSION_NUMBER < 0x10100000L BIO* sockBio = BIO_new(&sm_customBIOMethod); @@ -163,6 +167,7 @@ void TLSSocket_OpenSSL::createSSLHandle() { } SSL_set_bio(m_ssl, sockBio, sockBio); + SSL_set_tlsext_host_name(m_ssl, m_address.c_str()); SSL_set_connect_state(m_ssl); SSL_set_mode(m_ssl, SSL_MODE_AUTO_RETRY | SSL_MODE_ENABLE_PARTIAL_WRITE | SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER); @@ -178,6 +183,7 @@ void TLSSocket_OpenSSL::connect(const string& address, const port_t port) { try { m_wrapped->connect(address, port); + m_address = address; createSSLHandle(); diff --git a/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.hpp b/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.hpp index e30df680..233bd25a 100644 --- a/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.hpp +++ b/src/vmime/net/tls/openssl/TLSSocket_OpenSSL.hpp @@ -116,6 +116,8 @@ private: shared_ptr m_wrapped; + std::string m_address; + bool m_connected; byte_t m_buffer[65536];